blog.nintechnet.com
https://blog.nintechnet.com/authenticated-rce-vulnerability-in-wordpress-secure-file-manager-plugin-unpatched CVE-2020-35235
HIGH
Secure-file-manager plugin through 2.5 for WordPress Remote Code Execution
Record summary
CVE-2020-35235 has a selected CVSS score of 8.8 (high).
Description
vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 21, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
secure_file_managerBrowse themexa / secure_file_manager | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35235 wordpress.org
https://wordpress.org/plugins/secure-file-manager